3 ms·
First of all, I think the title has been chosen to click-bait the reader. Second, maybe the real problem is that USB was never designed to be the main way to ph
by Kayou 12y ago
First of all, I think the title has been chosen to click-bait the reader. Second, maybe the real problem is that USB was never designed to be the main way to physically share data, or not even to be used with external storage? Please correct me if I'm wrong. Maybe people should start exchanging data on media that are designed to store data, like a memory card, but maybe this medium can also be compromised.
- sophacles 12y agoI don't understand what you're saying. At the simplest level, there is no such thing as a bus which doesn't exchange data... even my keyboard and mouse are just sending data. At multiple levels there is software (therefore the potential for security bugs) in this process. My keyboard has software to convert a set of input pin readings into a form to put on the bus. It has a bus communications chip that has software (firmware whatever) to talk to a host. The other side has a similar set of software to send data from the bus to memory or to input pins on a chip. The chip runs software to interpret these signals into usefulness. There are lots of places for problems in there. Further, USB was designed from the beginning to allow block devices to transfer data. I don't quite get why this means it wasn't designed for data sharing - moving around physical, removable disks was the standard for data sharing for a long time when usb came out - back then most people couldn't reliable send big stuff over the network. The plan was definitely for sharing data. Basically the security issues come from the shape of the problem rather than a specific implementation of it. For example there's always someone doing "fun" things with network cards - another example of a device with DMA access and a microprocessor. If you can root the network card, you can get access to other parts of the device. So yeah - usb seems to be particularly easy to break, but it part of a generally hard problem. It would be nice to see a standard that takes the lessons of USB into account, and makes it much harder to break things.
- Kayou 12y agoI meant to say "share files" instead of "share data". But you're right, as I said, "Please correct me if I'm wrong". What I really wanted to say is that USB has been designed with so many different usages in mind that if you plug something in it, you should expect this "something" to be doing anything the USB has been designed for. And if you only want to share files and be sure it's not doing anything else, maybe you shouldn't be using USB. But at least this "problem" with USB is not as bad as with firewire or thunderbolt external storage.
- rainforest 12y ago> maybe this medium can also be compromised. Indeed it can. Bunnie & xobs recently showed how to get code running on the controller chips of SD cards [1]. With your own implementation you could have the card present alternative files (clean vs infected) to different machines based on read patterns [2] or just a mount count. Without an exploit for the kernel, you'd still need the user to click on one the files, however. That's not to say your suggestion isn't safer; SD cards don't present a threat to HID attacks (where a USB stick pretends to be a keyboard and is trusted to send inputs), but as with anything, it's not totally safe. [1] : http://www.bunniestudios.com/blog/?p=3554 http://www.bunniestudios.com/blog/?p=3554 [2] : http://events.ccc.de/congress/2012/Fahrplan/events/5327.en.html http://events.ccc.de/congress/2012/Fahrplan/events/5327.en.h...